Glossary

Understanding CPRA, California's privacy rights act

Taras Shynkarenko
Taras Shynkarenko
Updated: 6 min read
Understanding CPRA, California's privacy rights actUnderstanding CPRA, California's privacy rights act

TL;DR, Quick Answer

6 min read

CPRA is the California Privacy Rights Act, the 2020 ballot measure that amended the existing CCPA instead of replacing it, taking effect on January 1, 2023. It added a defined category of sensitive personal information, a consumer right to limit how a business uses that data, a right to correct inaccurate records, and a dedicated enforcement agency, the California Privacy Protection Agency. A business asking what CPRA means for its analytics setup has to look at whether it collects any of the categories CPRA singles out as sensitive, such as precise geolocation.

What does CPRA mean for a business collecting consumer data?

Short for the California Privacy Rights Act, CPRA is the law a business has to account for once it collects personal information from California residents beyond what the original CCPA already covered. The mechanism is that CPRA amended the CCPA in place, adding a defined category of sensitive personal information, new consumer rights, and a dedicated regulator, the California Privacy Protection Agency (CPPA), instead of creating a separate statute a business would need to track on its own. Read CPRA as an expansion of the same obligations a CCPA-compliant business already has, not a second, unrelated law.

What did CPRA change from the original CCPA?

CPRA changed three things beyond what the original CCPA already gave consumers: a right to correct inaccurate personal information a business holds, a right to limit how a business uses sensitive personal information, and a right to equal treatment for exercising any CCPA right, all three named directly by the CPPA as additions the CPRA made. The mechanism is enforcement moved from relying solely on the California Attorney General to a dedicated agency, the CPPA, created by the same ballot measure. Treat any CCPA compliance work finished before 2023 as a starting point, not a finished state, since CPRA layered these additions on top of it.

AspectOriginal CCPACPRA amendment
EnforcementCalifornia Attorney GeneralDedicated agency, the CPPA, with rulemaking power
Sensitive dataNo separate categorySensitive personal information defined, with a right to limit its use
CorrectionNo right to correctRight to correct inaccurate personal information added
Effective dateJanuary 1, 2020January 1, 2023

An office worker reviews paperwork containing personal details, the kind of records CPRA classifies as sensitive information.

What counts as sensitive personal information under CPRA?

Sensitive personal information under CPRA covers a named list that the CPPA states includes Social Security and driver's license numbers, information that would allow someone to access a financial account, precise geolocation, the contents of mail, email and text messages, genetic data, and biometric information used to identify a consumer, along with health status, sexual orientation, racial or ethnic background, citizenship, religious beliefs and union membership. The mechanism is that this category gets stronger protection than ordinary personal information, since a consumer can direct a business to limit its use of these specific fields to what is strictly necessary. Audit any analytics or product data for these exact categories, precise geolocation and account-access details being the two most common ones to appear in a tracking setup by accident.

What CPRA classifies as sensitive personal information
Identity and financeSSN, driver's license, financial account access
Location and communicationsPrecise geolocation, mail, email and text contents
Biological dataGenetic data, biometric data used to identify someone
Protected characteristicsHealth status, sexual orientation, race, religion, union membership
Source: California Privacy Protection Agency, cppa.ca.gov.

Who enforces CPRA, and what does the CPPA actually do?

The California Privacy Protection Agency enforces CPRA, a role the CPPA states covers "implementing and enforcing the CCPA as well as the Delete Act," the related law that sets data broker registration and deletion requirements. The mechanism is that the CPPA can write and amend regulations under the state's Administrative Procedures Act, in addition to bringing enforcement actions, giving it rulemaking power the Attorney General's office did not previously have over this statute. Watch the CPPA's own regulations page for current rulemaking, since the agency has continued adding requirements, including deadlines for automated decision-making technology rules that reach into 2027.

CPRA's timeline, from CCPA to ongoing rulemaking
1
January 1, 2020. The original CCPA takes effect, giving California consumers access, deletion and opt-out rights.
2
January 1, 2023. CPRA's amendments take effect, adding sensitive personal information rules, the right to correct data and the CPPA as enforcer.
3
Through 2027. The CPPA continues rulemaking, including deadlines for automated decision-making technology rules.
Dates as stated by the CPPA.

What rights does CPRA give a California consumer?

CPRA gives a California consumer the right to correct inaccurate personal information a business holds, the right to limit a business's use of sensitive personal information, and the right to equal treatment when exercising any of these rights, on top of the access, deletion and opt-out rights the original CCPA already provided. The mechanism is that each right creates a specific request a consumer can send a business, and the business has to have a working process to honor it within the statute's timelines. Build the limit-use and correction requests into the same request-handling process already built for CCPA deletion and opt-out requests, instead of as a separate system.

A smartphone displays a location pin on a map, illustrating the precise geolocation data CPRA asks analytics setups to limit.

What does CPRA ask of an analytics setup?

CPRA asks an analytics setup to avoid collecting sensitive personal information it does not need, since precise geolocation and any data that could identify a specific person from mail, messages or biometric signals falls under the category consumers can direct a business to limit. Flowsery's privacy-first analytics is built cookie-free and does not sample data, which keeps the categories a CPRA request has to touch smaller than a setup built on third-party cookies and device fingerprinting. Review what a tracking script actually captures against the GDPR and cookie policies already in place, since a setup built to avoid unnecessary personal data under one privacy law needs fewer changes to meet another.

Frequently Asked Questions

Does CPRA replace CCPA entirely?

No. CPRA amended the CCPA instead of replacing it, so the original law's access, deletion and opt-out rights still apply, with CPRA's additions layered on top. A business refers to "CCPA" and "CPRA" as the same statute at different points in its history, not two separate laws.

What is the difference between personal information and sensitive personal information under CPRA?

Personal information is the broader CCPA category covering anything that identifies or relates to a specific consumer, while sensitive personal information is a narrower list CPRA calls out by name, including precise geolocation, financial account access and biometric data. A consumer can direct a business to limit the use of the sensitive category specifically, a right that does not exist for ordinary personal information.

Does CPRA apply to every business that collects data from California residents?

CPRA applies based on thresholds tied to revenue, the volume of consumer data processed, or the share of revenue coming from selling personal information, the details of which are covered in when CCPA and CPRA apply. Check that resource against the current numbers before assuming a small business is automatically exempt.

Can a consumer sue over a CPRA violation directly?

CPRA carries a private right of action limited to specific data breach scenarios, separate from the CPPA's own enforcement authority, which covers the broader set of violations. The evolution from CCPA to CPRA covers how enforcement is split between the two paths.

What is the CPPA's rulemaking role beyond enforcement?

The CPPA can write and amend regulations under California's Administrative Procedures Act, which lets the agency add specific requirements over time, such as rules for automated decision-making technology, instead of leaving every detail to the original statute's text. A business tracks the CPPA's regulations page directly, since new rules can add obligations the statute itself does not spell out.

Does CPRA affect first-party analytics data the same way it affects data sold to brokers?

CPRA's sensitive personal information rules apply regardless of whether data is sold, since the right to limit covers how a business uses that data internally, not only whether it changes hands. A business selling data to brokers faces additional obligations under the related Delete Act, which the CPPA also enforces, on top of the CPRA rules that already apply to first-party use.

When did CPRA take effect?

CPRA was the 2020 ballot measure that amended the CCPA, and it took effect on January 1, 2023. The original CCPA had already been in effect since January 1, 2020, so the three years between the two dates gave businesses time to build on existing CCPA compliance work rather than start over. Any process built for CCPA before 2023 counts as the starting point CPRA's additions layer onto.

Flowsery
Flowsery

Start FREE Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

Did CPRA replace the California Attorney General as the enforcer?

CPRA moved enforcement from relying solely on the California Attorney General to a dedicated agency, the CPPA, created by the same ballot measure. The CPPA states its role covers implementing and enforcing the CCPA as well as the Delete Act. It also gained rulemaking power under the state's Administrative Procedures Act, authority the Attorney General's office did not previously have over this statute.

Is CPRA a California-only law?

CPRA applies to California residents and was created through a California ballot measure, so its rights and obligations are tied to that state. The agency that enforces it, the California Privacy Protection Agency, is a California state agency, and the California Attorney General held enforcement authority before the CPPA existed. A business outside California only needs to account for CPRA if it collects personal information from California residents.

What is the Delete Act, and how does it relate to CPRA?

The Delete Act is the related California law that sets data broker registration and deletion requirements, and the CPPA enforces it alongside CPRA. The two laws cover different obligations. CPRA's sensitive personal information rules apply regardless of whether a business sells data, while the Delete Act adds obligations specifically for businesses selling data to brokers. A business that only handles first-party data still has to meet CPRA's rules even without any Delete Act exposure.

Was This Article Helpful?

Let us know what you think!

See us more often in Google

One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.

Before you go...

Flowsery

Flowsery

Revenue-first analytics for your website

Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.

Real-time dashboard

Goal tracking

Cookie-free tracking

Related Glossary Terms

Related Articles